Vastal operates a portfolio of web-based content and community applications—including phpVid, Agent Zone, DVD Zone, Dating Zone, and Freelance Zone—that present typical attack surfaces for user-facing web platforms. Its vulnerabilities skew toward serious outcomes and frequently acquire public exploit code, driven by recurring input-handling weaknesses such as SQL injection and cross-site scripting that are endemic to web applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vastal over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15991CRITICAL Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via | Oct 31, 2017 | 9.8 | 42 | NO | YES |
CVE-2018-6367CRITICAL SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the /search_events.php category parameter. | Jan 29, 2018 | 9.8 | 41 | NO | YES |
CVE-2017-15975CRITICAL Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461. | Oct 29, 2017 | 9.8 | 41 | NO | YES |
CVE-2012-6526HIGH SQL injection vulnerability in show_code.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the code_id parameter. | Jan 31, 2013 | 7.5 | 31 | NO | YES |
CVE-2012-0982HIGH SQL injection vulnerability in search.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the price_from para | Feb 2, 2012 | 7.5 | 30 | NO | YES |
CVE-2008-4157HIGH SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2 | Sep 22, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-6209HIGH SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | Feb 20, 2009 | 7.5 | 29 | NO | YES |
CVE-2013-5311HIGH Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL commands via the "n" parameter to (1) browse_videos.php or (2) | Aug 19, 2013 | 7.5 | 28 | NO | YES |
CVE-2009-3495HIGH SQL injection vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the mag_id parameter, a different vector than CV | Sep 30, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-3953HIGH SQL injection vulnerability in keyword_search_action.php in Vastal I-Tech Shaadi Zone 1.0.9 allows remote attackers to execute arbitrary SQL commands via the tage parameter. | Sep 11, 2008 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vastal.
Media articles that mention a CVE ID that affects a product developed by Vastal — matched by CVE ID, not by vendor name.